Vulnerability Details CVE-2022-32531
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves
the bookkeeper client vulnerable to a man in the middle attack.
The problem affects BookKeeper client prior to versions 4.14.6 and 4.15.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.2%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2022-32531
-
cpe:2.3:a:apache:bookkeeper:-
-
cpe:2.3:a:apache:bookkeeper:4.0.0
-
cpe:2.3:a:apache:bookkeeper:4.1.0
-
cpe:2.3:a:apache:bookkeeper:4.10.0
-
cpe:2.3:a:apache:bookkeeper:4.11.0
-
cpe:2.3:a:apache:bookkeeper:4.11.1
-
cpe:2.3:a:apache:bookkeeper:4.12.0
-
cpe:2.3:a:apache:bookkeeper:4.12.1
-
cpe:2.3:a:apache:bookkeeper:4.13.0
-
cpe:2.3:a:apache:bookkeeper:4.14.0
-
cpe:2.3:a:apache:bookkeeper:4.14.1
-
cpe:2.3:a:apache:bookkeeper:4.14.2
-
cpe:2.3:a:apache:bookkeeper:4.14.3
-
cpe:2.3:a:apache:bookkeeper:4.14.4
-
cpe:2.3:a:apache:bookkeeper:4.14.5
-
cpe:2.3:a:apache:bookkeeper:4.15.0
-
cpe:2.3:a:apache:bookkeeper:4.2.0
-
cpe:2.3:a:apache:bookkeeper:4.2.1
-
cpe:2.3:a:apache:bookkeeper:4.2.3
-
cpe:2.3:a:apache:bookkeeper:4.2.4
-
cpe:2.3:a:apache:bookkeeper:4.3.0
-
cpe:2.3:a:apache:bookkeeper:4.3.1
-
cpe:2.3:a:apache:bookkeeper:4.3.2
-
cpe:2.3:a:apache:bookkeeper:4.4.0
-
cpe:2.3:a:apache:bookkeeper:4.5.0
-
cpe:2.3:a:apache:bookkeeper:4.5.1
-
cpe:2.3:a:apache:bookkeeper:4.6.0
-
cpe:2.3:a:apache:bookkeeper:4.6.1
-
cpe:2.3:a:apache:bookkeeper:4.6.2
-
cpe:2.3:a:apache:bookkeeper:4.7.0
-
cpe:2.3:a:apache:bookkeeper:4.7.1
-
cpe:2.3:a:apache:bookkeeper:4.7.2
-
cpe:2.3:a:apache:bookkeeper:4.7.3
-
cpe:2.3:a:apache:bookkeeper:4.8.0
-
cpe:2.3:a:apache:bookkeeper:4.8.1
-
cpe:2.3:a:apache:bookkeeper:4.8.2
-
cpe:2.3:a:apache:bookkeeper:4.9.0
-
cpe:2.3:a:apache:bookkeeper:4.9.1
-
cpe:2.3:a:apache:bookkeeper:4.9.2